Microsoft Entra ID (formerly Azure AD) connects to Authdog over OpenID Connect. Entra stays the system of record for your workforce; Authdog fronts your application and consumes the ID token.
Copy the redirect URL
In the Authdog console, select the project and environment, open Authentication > Providers, find Microsoft Entra ID, and click Enable. Copy the Redirect / Callback URL:
https://identity.authdog.com/api/v1/callback/<connectionId>Each environment has its own connection id, so its own redirect URL.
Register the application in Entra
- In the Entra admin center, open Identity > Applications > App registrations and click New registration.
- Set a name, keep Accounts in this organizational directory only, and add a Web redirect URI with the Authdog callback URL.
- Under Certificates & secrets, create a client secret and copy its value — it is shown once.
- Copy the Application (client) ID from the Overview page.
- Note the OpenID Connect metadata document URL, e.g.
https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration.
Configure Authdog
| Field | Value |
|---|---|
| Client ID | Application (client) ID |
| Client secret | The secret value from Certificates & secrets |
| Discovery URL | The OpenID Connect metadata document URL (the /.well-known/openid-configuration suffix is optional) |
| Email domains | Domains routed to this connection, e.g. acme.com |
Save, then toggle the connection active.
Test the connection
- On the saved connection, click Test connection. Authdog validates the required fields, then fetches the discovery document and confirms it carries
authorization_endpoint,token_endpoint, andjwks_uri. Failures come back with named codes —unreachablewhen the document cannot be fetched,missing_endpointwhen it is the wrong document. - Then run a real login: open the Login URL, complete the Entra prompt, and confirm the user appears under Users with an Entra identity linked.
Rotate the secret
Entra client secrets expire. When one does:
- Create a new secret under Certificates & secrets.
- Paste it into the connection's Client secret field and save.
No downtime: the old secret keeps working until Entra expires it. Secret rotations are recorded in the environment audit log.
Troubleshooting
| Symptom | Cause |
|---|---|
unreachable fault on discovery |
Wrong tenant id in the discovery URL, or the app registration was deleted |
missing_endpoint fault |
The URL points at a v1 endpoint or a non-OIDC document — use the v2.0 metadata URL |
AADSTS700016 |
The client ID does not exist in this tenant |
AADSTS50011 |
The redirect URI is not registered on the app registration |
| User looped back to sign-in | Email domain not listed on the connection |
Related
| Read | To learn how to |
|---|---|
| Enterprise SSO | Understand the SSO model and discovery |
| SCIM provisioning | Sync Entra users and groups over SCIM |
| Okta | Connect Okta over SAML instead |